VulnerabilitiesHIGH

Vulnerabilities - CISA Adds Apple, Laravel, Craft CMS Flaws

SASecurity Affairs
CVE-2025-31277CVE-2025-32432CVE-2025-54068
🎯

Basically, CISA found serious security flaws in popular software that need fixing.

Quick Summary

CISA has added critical vulnerabilities in Apple, Laravel Livewire, and Craft CMS to its catalog. These flaws pose serious risks to users. Immediate action is required to mitigate potential exploits.

The Flaw

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has recently added several critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. Among these are multiple flaws affecting Apple products, Laravel Livewire, and Craft CMS. Notably, the vulnerabilities include CVE-2025-32432, a code injection vulnerability in Craft CMS, and CVE-2025-54068, linked to Laravel Livewire. These vulnerabilities have been assigned high CVSS scores, indicating their severity and potential for exploitation.

The vulnerabilities were identified following reports from various cybersecurity entities, including Google Threat Intelligence Group and Orange Cyberdefense. The flaws can be exploited by threat actors to execute malicious code, potentially leading to data breaches or unauthorized access to sensitive information.

What's at Risk

The risks associated with these vulnerabilities are significant. For instance, CVE-2025-32432 has been exploited in the wild, allowing attackers to breach servers and steal data. The exploitation of these vulnerabilities can lead to severe consequences, including data loss and reputational damage for affected organizations.

CISA has emphasized the importance of addressing these vulnerabilities promptly, particularly for federal agencies, which are required to remediate these flaws by April 3, 2026. The vulnerabilities not only affect federal agencies but also pose risks to private organizations that utilize these platforms.

Patch Status

Fortunately, patches have been released for the identified vulnerabilities. Craft CMS has addressed CVE-2025-32432 in its versions 3.9.15, 4.14.15, and 5.6.17. Similarly, the Yii framework, which Craft CMS relies on, has released a patch to mitigate the input validation flaw. It is crucial for users and organizations to apply these updates as soon as possible to protect their systems from potential exploits.

However, the vulnerabilities in Apple products remain a concern, as they have been linked to an iOS exploit kit known as DarkSword. This kit targets multiple Apple vulnerabilities, indicating a broader threat landscape that could affect a wide range of users.

Immediate Actions

Organizations and users should take immediate action to mitigate the risks associated with these vulnerabilities. Here are some recommended steps:

  • Update software: Ensure that all affected systems are updated to the latest versions that include the necessary patches.
  • Monitor systems: Implement monitoring solutions to detect any suspicious activity related to these vulnerabilities.
  • Educate staff: Train employees about the risks and signs of exploitation to enhance overall security awareness.

By taking these proactive measures, organizations can significantly reduce their exposure to the risks posed by these newly identified vulnerabilities.

🔒 Pro insight: The addition of these vulnerabilities to the KEV catalog highlights the ongoing threat landscape and the need for immediate remediation efforts.

Original article from

Security Affairs · Pierluigi Paganini

Read Full Article

Related Pings

CRITICALVulnerabilities

CVE-2026-21992 - Oracle Fixes Critical RCE Flaw

Oracle has addressed a critical RCE vulnerability in Identity Manager. This flaw allows attackers to gain system control without authentication. Immediate updates are essential to safeguard sensitive data and maintain system integrity.

Security Affairs·
HIGHVulnerabilities

Vulnerabilities - ScreenConnect Servers and SharePoint Flaw Exploited

Recent vulnerabilities in ScreenConnect and Microsoft SharePoint are under active exploitation. Organizations using these platforms must patch them immediately to avoid serious breaches. Stay informed and secure your systems now!

Help Net Security·
CRITICALVulnerabilities

Oracle Patches Critical CVE-2026-21992 - Unauthenticated RCE

Oracle has patched a critical vulnerability in its Identity Manager and Web Services Manager. This flaw allows unauthenticated remote code execution, posing serious risks to users. Immediate updates are essential to safeguard systems.

The Hacker News·
HIGHVulnerabilities

KACE Vulnerability - Critical Exploitation in Education Sector

A critical vulnerability in Quest KACE, CVE-2025-32975, has been exploited in attacks, primarily impacting the education sector. Organizations must act quickly to apply patches and protect their systems.

SecurityWeek·
HIGHVulnerabilities

Vulnerabilities - PolyShell Flaw Exposes Magento to Attacks

A critical flaw in Magento and Adobe Commerce allows unauthorized file uploads, risking XSS attacks. Many online stores are affected, highlighting the urgent need for security measures. Immediate action is essential to protect sensitive data and maintain operational integrity.

Security Affairs·
HIGHVulnerabilities

Vulnerabilities - CISA Flags Apple and CMS Bugs for Patching

CISA has flagged critical vulnerabilities in Apple and CMS platforms. Federal agencies must patch these by April 2026 to avoid exploitation. Stay ahead of threats by ensuring timely updates.

The Hacker News·